Re: [VOTE] RFC: Multibyte Char Handling
| From: | Yasuo Ohgaki | Date: | Sun, 02 Feb 2014 02:47:38 +0000 |
| Subject: | Re: [VOTE] RFC: Multibyte Char Handling | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71966@lists.php.net to get a copy of this message | ||
Hi all,
Since there are comments that there should be 2 RFCs.
Here is 2 RFCs for multibyte encoding handling security issues.
Short term resolution - add functions to mbstrings
https://wiki.php.net/rfc/multibyte_char_handling
Long term resolution - compile mbstring-ng as default (replace mbstring if
possible)
https://wiki.php.net/rfc/altmbstring
I would like to start vote soon.
Please comment now.
Thank you.
--
Yasuo Ohgaki
yohgaki@ohgaki.net
On Sun, Jan 26, 2014 at 9:23 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Hi all,
>
> This RFC is to fix CVE-2014-1239.
>
> https://wiki.php.net/rfc/multibyte_char_handling
>
> Adding required functions to mbstring and provide them
> from PHP 5.3 and up and replacing mbstring to mbstring-ng
> for future releases.
>
> Thank you for voting!
>
> Regards,
>
> --
> Yasuo Ohgaki
> yohgaki@ohgaki.net
>